Also, using your own VPN, you're likely the only one using it. There's zero anonymity. And so an adversary would figure that out, and then focus on the VPS provider.
The sad truth is that you can't trust anyone. So your best option is distributing trust. That way, compromise depends on collusion among providers. Or on their joint compromise by your adversaries.
That's how Tor is designed. User traffic gets routed through three relays. User clients pick the relays in advance, for each circuit. The first (guard) relay only knows the IPs of the user and the second (middle) relay. The middle relay only knows the IPs of the guard and the third (exit) relay. And the exit relay only knows the IPs of the middle relay and the internet resource.
And you can do the same thing with VPN services. That is, nested VPN chains. You can do it either using multiple pfSense VMs as VPN gateways.[0] Or less securely, just with routing and iptables.[1,2]
0) https://www.ivpn.net/privacy-guides/advanced-privacy-and-ano...
The benefits to privacy would be:
- It may still make it harder for your ISP to track you, which can be worthwhile.
- It can still be useful to help hide your physical location, since your IP won't be in the same county as you. That's also not nothing.
For 3rd-party sites, you'll be making your traffic easier to correlate across domains, locations, etc... Up to you whether or not that's part of your threat model.
- Rolling your own VPN (control your own infrastructure)
- Using an existing VPN service (crowd-based anonymity)
- Doing nothing (privacy nihilism)
Each decision has their own benefits and tradeoffs. If you're someone who torrents, you should probably be using crowd-based anonymity. If you really dislike the trust relationship you have with your VPN and you're technically inclined, you can roll your own VPN. If you don't want to spend the time worrying about this stuff, setting up a VPN on its own and doing nothing else won't make you private anyway.
I (very cautiously) lean towards advising people to use an existing VPN service, but that's not a strong opinion. I do think people who argue that rolling your own VPN is the only sensible choice are either full of crap, or haven't thought through the actual threat models real people face.
There's a big movement in some portions of the security industry to say that moving trust around isn't valuable, and that doing nothing is better than centralizing your trust. I'm not going to mince words, I think that's a really dumb perspective.
Sure, but they retain records.
I don't trust my VPN provider. But I do trust Swiss privacy laws. At least more than I trust my American cable provider.
They're also already committed to censorship, so I don't fathom how they'd run a VPN service.
Google, Amazon, etc. are huge businesses which get a ton of scrutiny by large business and government customers: if they get caught cheating, especially in a way which jeopardize customer data, they’ll lose orders of magnitude more money than any VPN user is worth and as a publicly traded company in the United States they’re going to have a much harder time avoiding legal consequences.
> and the people behind it can just setup another shell company
I think this may be true for the smaller ones, but not for the larger companies, like for example ProtonVpn. They would loose their entire business if they get caught "cheating".
> Google, Amazon... if they get caught cheating... For example Google is getting caught with privacy violations constantly/on a regular basis. For example lately they were caught following Android devices even with Location Services turned off!